156-215.80 Check Point Certified Security Administrator (CCSA R80) Practice Questions
Prepare for 156-215.80 with more than an answer.
Unlock the full exam and previous versions
- v1Check Point Certified Security Administrator (CCSA) R82 381 questions Locked
- 156-215.80Legacy Check Point Certified Security Administrator (CCSA R80) 554 questions Current
- 156-215.81Legacy Check Point Certified Security Administrator (CCSA) R81 210 questions Locked
- 156-215.81.20Legacy Check Point Certified Security Administrator (CCSA) R81.20 231 questions Locked
- 1
Which of the following statements is TRUE about R80 management plug-ins?
Show answer details
Correct answer: C
A management plug-in interacts with a Security Management Server to provide new features and support for new products in R80 environments. Management plug-ins extend SmartConsole functionality by adding support for third-party security products, new Check Point blades, or custom security solutions. These plug-ins integrate directly with the R80 management infrastructure, allowing administrators to manage additional security components through the familiar SmartConsole interface. Examples include plug-ins for endpoint security, threat intelligence feeds, or specialized security appliances that can be managed alongside Check Point gateways through a unified management platform.
- 2
Gaia can be configured using the or .
Show answer details
Correct answer: C
Explanation:
Configuring Gaia for the First Time In This Section:
Running the First Time Configuration Wizard in WebUI Running the First Time Configuration Wizard in CLI
After you install Gaia for the first time, use the First Time Configuration Wizard to configure the system and the Check Point products on it. - 3
Where can you trigger a failover of the cluster members?
- Log in to Security Gateway CLI and run command clusterXL_admin down.
- In SmartView Monitor right-click the Security Gateway member and select Cluster member stop.
- Log into Security Gateway CLI and run command cphaprob down.
Show answer details
Correct answer: C
- 4
Which utility allows you to configure the DHCP service on GAIA from the command line?
Show answer details
Correct answer: C
Reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Splat_AdminGuide/51548.htm
NOTE: Question must be wrong because no answer is possible for GAIA system, this must be SPLAT version.
DHCP CLI configuration for GAIA reference: https://sc1.checkpoint.com/documents/R76/CP_R76_Gaia_WebAdmin/73181.htm#o80096
- 5
Which VPN routing option uses VPN routing for every connection a satellite gateway handles?
Show answer details
Correct answer: D
On the VPN Routing page, enable the VPN routing for satellites section, by selecting one of these options:
- 6
Which product correlates logs and detects security threats, providing a centralized display of potential attack patterns from all network devices?
Show answer details
Correct answer: B
Explanation:
SmartEvent correlates logs from all Check Point enforcement points, including end-points, to identify suspicious activity from the clutter. Rapid data analysis and custom event logs immediately alert administrators to anomalous behavior such as someone attempting to use the same credential in multiple geographies simultaneously.
- 7
Assuming you have a Distributed Deployment, what will be the effect of running the following command on the Security Management Server?

Show answer details
Correct answer: A
Explanation:
This command uninstall actual security policy (already installed) Reference:
https://sc1.checkpoint.com/documents/R77/CP_R77_SecurityGatewayTech_WebAdmin/6751.htm - 8
Which of the following is NOT an integral part of VPN communication within a network?
Show answer details
Correct answer: A
VPN key is not an integral part of VPN communication within a Check Point R80 environment. The three essential components for VPN communication are VPN communities (which define groups of participating gateways), VPN trust entities (the security gateways and management server that participate in the VPN), and VPN domains (networks that can be accessed through each gateway). While encryption keys are used in the cryptographic process, the term "VPN key" is not a standard Check Point component. In R80 SmartConsole, administrators configure VPN communities to establish mesh or star topologies, define encryption domains through VPN trust entities, and specify accessible networks via VPN domains.
- 9
Two administrators Dave and Jon both manage R80 Management as administrators for ABC Corp. Jon logged into the R80 Management and then shortly after Dave logged in to the same server. They are both in the Security Policies view. From the screenshots below, why does Dave not have the rule no.6 in his SmartConsole view even though Jon has it his in his SmartConsole view?

Show answer details
Correct answer: D
Explanation:
When an administrator logs in to the Security Management Server through SmartConsole, a new editing session starts. The changes that the administrator makes during the session are only available to that administrator. Other administrators see a lock icon on object and rules that are being edited. To make changes available to all administrators, and to unlock the objects and rules that are being edited, the administrator must publish the session.
- 10
Vanessa is firewall administrator in her company; her company is using Check Point firewalls on central and remote locations, which are managed centrally by R80 Security Management Server. One central location has an installed R77.30 Gateway on Open server. Remote location is using Check Point UTM-1 570 series appliance with R71. Which encryption is used in Secure Internal Communication (SIC) between central management and firewall on each location?
Show answer details
Correct answer: A
Explanation:
Gateways above R71 use AES128 for SIC. If one of the gateways is R71 or below, the gateways use 3DES.
Reference:
